LukaOTP Privacy Policy
LukaOTP processes TOTP data locally in Chrome. The developer does not receive or transmit user data. LukaOTP does not sell, share, or disclose locally processed information.
What the extension processes
- PII: account or service names and labels, which may contain an email address or email username, for labeling, searching, grouping, and display.
- Authentication information: TOTP provisioning keys, encrypted account records, and generated verification codes for secure storage and code generation.
- Master password: handled in memory to derive the encryption key; it is not stored or transmitted.
- Website content: after you choose “Scan current tab,” one screenshot of the currently visible content is processed locally to recognize a QR code. A selected local image is processed the same way.
Storage, retention, and deletion
Account names, possible email usernames, TOTP keys, and metadata are encrypted with AES-256-GCM and stored in Chrome’s local extension storage. The master password, decrypted values, QR screenshots, imported image bytes, and generated codes are used only in memory for the active operation or unlocked session and are not intentionally retained after processing, cancellation, locking, or closing.
Clear the extension’s local data, browser data, or uninstall the extension to delete the local vault. There is no developer-held copy, cloud synchronization, or recovery service.
Network requests, sharing, and remote code
LukaOTP makes no external network requests and transmits no user data. It does not use analytics, advertising, cloud storage, or third-party data-sharing services. All executable extension logic is packaged with the extension; remote code is not used.
Chrome Web Store User Data Policy
LukaOTP follows the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the stated user-facing features, not for advertising, creditworthiness, or unrelated purposes, and is not sold or transferred to third parties.
Permissions
storage saves the encrypted local vault. activeTab permits the one-time visible-tab capture only after you explicitly request QR scanning. The extension does not request persistent website access or browsing history.